Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Facebook Password-Reset Spam is Bredolab Botnet Attack
ZDnet ^ | 10/27/09 | Ryan Naraine

Posted on 10/28/2009 1:00:51 PM PDT by nickcarraway

Virus hunters are raising the alarm for a large-scale spam attack that uses fake Facebook password-reset messages to trick PC users into downloading a dangerous piece of malware.

The malicious executable is linked to the Bredolab botnet, which has been linked to massive spam runs and identity-theft related attacks.

Here’s a sample of the Facebook password-reset messages hitting e-mail inboxes this morning:

According to Websense, the address of the sender is spoofed to display “support@facebook.com,” a trick commonly used to trick targets into believing it’s a legitimate e-mail from the popular social network.

The messages contain a .zip file attachment with an .exe file that connects to two servers to download additional malicious files and joins the Bredolab botnet which means the attackers have full control of the PC, such as steal customer information, send spam emails. One of the servers is in the Netherlands and the other one in Kazakhstan.


TOPICS: Business/Economy; Computers/Internet
KEYWORDS: botnets; facebook; phishing

1 posted on 10/28/2009 1:00:52 PM PDT by nickcarraway
[ Post Reply | Private Reply | View Replies]

To: nickcarraway

Yeah I got this yesterday, and checked with our IT person who confirmed the attachment was a virus.

It was kind of a stupid attempt because I don’t have a Facebook account and I wasn’t the addressee on the email.


2 posted on 10/28/2009 1:06:34 PM PDT by kaehurowing
[ Post Reply | Private Reply | To 1 | View Replies]

To: nickcarraway

Got it and deleted it.

I knew there was a problem when it was sent to one of my alpacas’ email address.

If she has joined Facebook she has some explaining to do.


3 posted on 10/28/2009 1:09:42 PM PDT by mrs. a (It's a short life but a merry one...)
[ Post Reply | Private Reply | To 1 | View Replies]

To: mrs. a

Good thing you deleted it. Alpacas are especially vulnerable to phishing spoofs.


4 posted on 10/28/2009 1:12:28 PM PDT by nickcarraway
[ Post Reply | Private Reply | To 3 | View Replies]

To: nickcarraway

Who falls for such simplistic attempts?

The email begins with “Hey!” from a multi-million dollar online service?

And then announces they’ve changed the password - out of the blue?

Some folks deserve to get infected.


5 posted on 10/28/2009 2:02:11 PM PDT by Cletus.D.Yokel (FreepMail me if you want on the Bourbon ping list!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: nickcarraway

Thanks for the warning. Scary stuff!


6 posted on 10/28/2009 2:44:41 PM PDT by luvie (2010 is Conservatives' to win....or lose. So....LET'S WIN!!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Cletus.D.Yokel

Actually, a lot of Web 2.0 companies use pretty informal communication.


7 posted on 10/28/2009 2:45:45 PM PDT by nickcarraway
[ Post Reply | Private Reply | To 5 | View Replies]

To: nickcarraway

I understand that but the password thing? Really?

That’s analogous to getting a phonecall from someone who claims to have your cat and wants ransom...and you don’t have a cat


8 posted on 10/28/2009 3:34:19 PM PDT by Cletus.D.Yokel (FreepMail me if you want on the Bourbon ping list!)
[ Post Reply | Private Reply | To 7 | View Replies]

To: mrs. a

So if I just got a Facebook Friends Request from your Alpaca, I should delete it?


9 posted on 10/28/2009 3:40:56 PM PDT by PERKY2004 (Proud Military Wife -- Please pray for our troops!)
[ Post Reply | Private Reply | To 3 | View Replies]

To: PERKY2004

Absolutely! She’s a sneaky little devil. Just wants to steal your identity and go shopping on Rodeo Drive...


10 posted on 10/28/2009 4:22:57 PM PDT by mrs. a (It's a short life but a merry one...)
[ Post Reply | Private Reply | To 9 | View Replies]

To: PERKY2004

Whatever you do, don’t “poke” the alpaca.


11 posted on 10/28/2009 4:25:32 PM PDT by RedWhiteBlue
[ Post Reply | Private Reply | To 9 | View Replies]

To: nickcarraway

i got it and ignored it...


12 posted on 10/28/2009 4:26:50 PM PDT by latina4dubya ( self-proclaimed tequila snob)
[ Post Reply | Private Reply | To 1 | View Replies]

To: PERKY2004
So if I just got a Facebook Friends Request from your Alpaca, I should delete it?

LMAO

better check with PETA first......

13 posted on 10/28/2009 4:28:38 PM PDT by nascarnation
[ Post Reply | Private Reply | To 9 | View Replies]

To: latina4dubya

This email got thru our spam filter twice this morning.
I work for a very large international defense contractor.
I knew it was garbage, I have no facebook or any of that
stuff. I have little confidence in our IT system.


14 posted on 10/28/2009 4:30:08 PM PDT by jusduat (probably lost)
[ Post Reply | Private Reply | To 12 | View Replies]

To: mrs. a

All alpacas long for a Pashmina coat.


15 posted on 10/28/2009 5:37:20 PM PDT by nickcarraway
[ Post Reply | Private Reply | To 10 | View Replies]

To: jusduat
This email got thru our spam filter twice this morning. ... I have little confidence in our IT system.

I wouldn't blame them. It's an arm's race that the SPAMmers will always win and your friendly IT guys have productive work to do in their "spare" time besides stopping SPAM.

16 posted on 10/28/2009 6:45:38 PM PDT by altair (All I want for Christmas is NO legislation passed for the rest of the year)
[ Post Reply | Private Reply | To 14 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson